Bitget CEO Blames North Korea for $387.5 Million Wallet Breach
Bitget CEO Gracy Chen said on September 25, 2026, that state-sponsored hackers linked to North Korea stole approximately $387.5 million from the Singapore-based cryptocurrency exchange after breaching its backend wallet infrastructure. Chen said the platform's User Protection Fund — which holds more than $464 million — will be used to cover the full amount, so no user deposits are expected to be permanently lost.
Incident Summary
| Field | Details |
|---|---|
| Platform | Bitget (Singapore-based crypto exchange) |
| Amount Stolen | $387.5 million |
| Assets Taken | ETH, XRP, USDC, and other cryptocurrencies |
| Attributed To | North Korea (CEO cites links to Lazarus Group) |
| Reimbursement Fund | User Protection Fund |
| Fund Size | Over $464 million |
| Attribution Status | Company claim; independent government confirmation not yet issued |
How the Theft Reportedly Happened
Initial Breach and Escalation
According to Chen, attackers first compromised roughly $175 million before the theft escalated to a total of $387.5 million as investigators continued tracing unauthorized outflows. Bitget said the intrusion targeted its backend wallet services systems, with hackers exploiting vulnerabilities there to enable transfers that were not authorized by the platform.
Assets Drained
The stolen funds spanned multiple cryptocurrencies, including ETH, XRP, and USDC, suggesting the attackers had broad access across several wallet pools rather than a single isolated hot wallet.
Emergency Response
Bitget suspended withdrawals platform-wide while it investigated the scope of the breach and worked to trace and, where possible, freeze the stolen assets before they could be laundered through mixers or cross-chain bridges — a standard early-stage response for exchanges hit by large-scale wallet compromises.
The North Korea Attribution: Evidence and Confidence Level
What Bitget Says Points to the DPRK
Chen and Bitget's investigators pointed to a combination of IP addresses, behavioral patterns, and on-chain transaction signatures they say match those associated with North Korean state-sponsored hacking groups. Blockchain analysts working the case reportedly identified overlaps with techniques used in past Lazarus Group operations, the umbrella threat actor long tied to Pyongyang's cryptocurrency-theft campaigns.
Investigators Involved
Bitget said it engaged outside security firms, including Mandiant and SlowMist, to assist with forensic analysis of the breach. Chen stated the company has "notified relevant authorities and are cooperating fully with them globally," indicating law enforcement agencies have been looped into the investigation.
How Confident Is This Attribution?
It is important to note this attribution is currently Bitget's own claim, corroborated by blockchain forensic patterns rather than a confirmed government determination. No U.S. Treasury, FBI, or South Korean government statement had been issued attributing the theft to North Korea at the time of publication. On-chain and infrastructure indicators consistent with Lazarus Group / TraderTraitor-style tradecraft are a strong signal given the group's long history of targeting crypto platforms, but formal attribution typically takes weeks as investigators complete wallet-tracing and infrastructure analysis.
The User Protection Fund and What It Means for Users
Bitget said its User Protection Fund, which holds more than $464 million, will be used to make affected users whole, fully covering the $387.5 million loss. The fund functions as a self-insurance reserve exchanges maintain specifically to absorb losses from hacks, exploits, or operational failures without directly touching customer-held assets outside the compromised wallets.
To aid recovery of the stolen funds, Bitget said it is offering:
- A 5% bounty to any platform that voluntarily freezes funds traced back to the theft
- An additional 5% bounty for parties that assist in the successful recovery of stolen assets
Withdrawals remained suspended as of publication while the platform completes its security review, meaning users could face short-term access delays even though the company maintains no funds will be permanently lost.
North Korea's Pattern of Crypto-Platform Theft
If confirmed, this incident would extend a well-documented pattern: North Korea has been repeatedly linked to some of the largest cryptocurrency heists in history, with analysts tracking DPRK-linked cyber operations estimating the regime stole more than $2 billion through crypto theft in the past year alone, and over $3 billion cumulatively since 2017. Proceeds from these operations are widely assessed by international investigators to help fund North Korea's sanctioned weapons and missile programs, making crypto exchanges a persistent, high-value target for Pyongyang's state-sponsored hacking units.
Impact Assessment
| Impact Area | Description |
|---|---|
| User Funds | Expected to be fully covered by the User Protection Fund; no anticipated permanent loss to depositors |
| Platform Availability | Withdrawals suspended during the investigation, delaying user access to funds |
| Reputational Risk | Adds Bitget to a growing list of exchanges targeted by DPRK-linked actors in 2026 |
| Sector-Wide Scrutiny | Likely to renew regulatory pressure on exchange hot-wallet and backend wallet-service security |
| Geopolitical | Reinforces evidence of North Korea's continued reliance on crypto theft to fund state programs |
Recommendations
For Exchanges and Custodians
Audit backend wallet service architecture for privilege-escalation paths, enforce multi-party computation (MPC) or hardware-backed signing for high-value transfers, and implement real-time anomaly detection on outbound wallet transactions. Segment wallet infrastructure so a single service compromise cannot cascade into transfers across multiple asset pools.
For Bitget Users
- Monitor official Bitget channels only — do not click links in unsolicited emails or social media messages referencing this incident
- Be alert for phishing campaigns that impersonate Bitget support offering "priority reimbursement" or asking for wallet credentials
- Confirm any communication about fund status through Bitget's verified app or website before taking action
For Security Teams and Blockchain Analysts
- Track and flag wallet addresses associated with the stolen funds as they move through exchanges, mixers, and bridges
- Share indicators of compromise with industry partners given the suspected Lazarus Group / TraderTraitor nexus
- Treat this incident as a reminder to review internal wallet-service access controls against known DPRK TTPs
Key Takeaways
- Bitget CEO Gracy Chen says North Korean state-sponsored hackers stole $387.5 million by exploiting the exchange's backend wallet services.
- The theft escalated from an initial $175 million before reaching its final total, spanning ETH, XRP, USDC, and other assets.
- Attribution to North Korea rests on IP addresses, behavioral patterns, and on-chain signatures resembling Lazarus Group tradecraft — a strong but not yet government-confirmed determination.
- Bitget's $464 million User Protection Fund is expected to fully cover the loss, with withdrawals temporarily suspended during recovery.
- Bitget is offering 5% bounties for voluntary fund freezing and for assistance recovering stolen assets.
- The incident fits North Korea's broader, well-documented pattern of targeting cryptocurrency platforms to fund state programs, with estimated cumulative theft exceeding $3 billion since 2017.